This is a vital problem as a result of completely different PLC fashions from the identical vendor and even completely different producers would possibly share a susceptible part, with the remainder of the firmware being considerably completely different. Moreover, distributors generally patch a vulnerability reported in a single mannequin with out comprehensively assessing whether or not the identical flaw impacts others of their product line.
For instance, again in June, Forescout reported seeing exploit makes an attempt for a vulnerability they discovered and reported in serial-to-IP converters from Lantronix (CVE-2025-67038). The producer initially launched patches just for the EDS5000 and EDS3000 sequence of controllers, however after in-the-wild exploitation got here to mild 4 months later, it recognized and launched patches for extra system fashions: G520 sequence, X300 sequence, E210 and E220 sequence.
“I do imagine that in case producers don’t carry out a complete evaluation of fashions affected by a vulnerability, AI can now assist attackers to do it and to port exploits to fashions that will not have been patched,” Daniel dos Santos, VP of analysis at Forescout, tells CSO.


